Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
BID:31178
Info
Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
| Bugtraq ID: | 31178 |
| Class: | Design Error |
| CVE: |
CVE-2008-7012 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2008 12:00AM |
| Updated: | Apr 16 2015 05:54PM |
| Credit: | Eric Beaulieu |
| Vulnerable: |
Accellion File Transfer FTA_7_0_178 Accellion File Transfer FTA_7_0_135 Accellion File Transfer 0 |
| Not Vulnerable: |
Accellion File Transfer FTA_7_0_189 |
Discussion
Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
Accellion File Transfer Appliance is prone to an open-email-relay vulnerability.
An attacker could exploit this issue by constructing a script that would send unsolicited spam to an unrestricted amount of email addresses from a forged email address.
This issue affects Accellion File Transfer Appliance prior to FTA_7_0_189.
Accellion File Transfer Appliance is prone to an open-email-relay vulnerability.
An attacker could exploit this issue by constructing a script that would send unsolicited spam to an unrestricted amount of email addresses from a forged email address.
This issue affects Accellion File Transfer Appliance prior to FTA_7_0_189.
Exploit / POC
Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
Attackers may exploit this issue by using readily available network utilities.
The following proof of concept is available:
Attackers may exploit this issue by using readily available network utilities.
The following proof of concept is available:
Solution / Fix
Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
Solution:
The vendor has released an update. Please contact the vendor for details.
Solution:
The vendor has released an update. Please contact the vendor for details.
References
Accellion File Transfer Appliance Error Report Message Open Email Relay Vulnerability
References:
References:
- Accellion File Transfer - SPAM Engine Vulnerabilities (Eric Beaulieu)
- Vendor Homepage (Accellion)